Logic error in the SID/Name translation functionality in smbd in Samba 3.0.23d through 3.0.25pre2 allows local users to gain temporary privileges and execute SMB/CIFS protocol operations via unspecified vectors that cause the daemon to transition to the root user
Published May 14, 2007
7.2
HIGHCVSS 2.0
EPSS 0.78%
Description
Logic error in the SID/Name translation functionality in smbd in Samba 3.0.23d through 3.0.25pre2 allows local users to gain temporary privileges and execute SMB/CIFS protocol operations via unspecified vectors that cause the daemon to transition to the root user.
Affected products
No data.
Configuration 1
Configuration 2
- 4.0
- 5.0
Configuration 3
- 6.06
- 6.10
- 7.04
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Red Hat statement
Not vulnerable. These issues did not affect the versions of Samba as shipped with Red Hat Enterprise Linux 2.1, 3, 4, or 5.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:L/AC:L/Au:N/C:C/I:C/A:C
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (18 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.78% (0.00777) | 54.19th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.78% (0.00783) | 51.06th | v5 (v2026.06.15) |
| Aug 31, 2025 | 1.38% (0.01384) | 79.55th | v4 (v2025.03.14) |
| Aug 30, 2025 | 3.62% (0.03621) | 87.35th | v4 (v2025.03.14) |
| Jul 26, 2025 | 12.22% (0.12221) | 93.53th | v4 (v2025.03.14) |
| Mar 30, 2025 | 8.83% (0.08832) | 91.72th | v4 (v2025.03.14) |
| Mar 29, 2025 | 10.59% (0.10587) | 88.72th | v4 (v2025.03.14) |
| Mar 20, 2025 | 8.83% (0.08832) | 91.83th | v4 (v2025.03.14) |
| Mar 17, 2025 | 10.45% (0.10452) | 92.67th | v4 (v2025.03.14) |
| Dec 17, 2024 | 24.88% (0.24884) | 96.66th | v3 (v2023.03.01) |
| Oct 6, 2024 | 13.80% (0.13796) | 95.74th | v3 (v2023.03.01) |
| Aug 17, 2024 | 18.81% (0.18808) | 96.33th | v3 (v2023.03.01) |
| Jul 9, 2024 | 21.79% (0.21790) | 96.50th | v3 (v2023.03.01) |
| Mar 7, 2023 | 52.85% (0.52855) | 96.98th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.55% (0.01547) | 74.98th | v2 (v2022.01.01) |
| Feb 23, 2023 | 1.55% (0.01547) | 74.94th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.55% (0.01547) | 72.92th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.55% (0.01547) | 51.82th | v2 (v2022.01.01) |
References (37)
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c01078980 vendor-advisoryx_refsource_HPBroken Link
- http://lists.suse.com/archive/suse-security-announce/2007-May/0006.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://osvdb.org/34698 vdb-entryx_refsource_OSVDBBroken Link
- http://secunia.com/advisories/25232 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/25241 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/25246 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/25251 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/25255 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/25256 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/25259 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/25270 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/25289 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/25675 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://secunia.com/advisories/25772 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://security.gentoo.org/glsa/glsa-200705-15.xml vendor-advisoryx_refsource_GENTOOThird Party Advisory
- http://securityreason.com/securityalert/2701 third-party-advisoryx_refsource_SREASONThird Party Advisory
- http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.475906 vendor-advisoryx_refsource_SLACKWAREMailing ListThird Party Advisory
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-102964-1 vendor-advisoryx_refsource_SUNALERTBroken Link
- http://sunsolve.sun.com/search/document.do?assetkey=1-66-200588-1 vendor-advisoryx_refsource_SUNALERTBroken Link
- http://www.debian.org/security/2007/dsa-1291 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:104 vendor-advisoryx_refsource_MANDRIVABroken Link
- http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.012.html vendor-advisoryx_refsource_OPENPKGThird Party Advisory
- http://www.samba.org/samba/security/CVE-2007-2444.html x_refsource_CONFIRMPatchVendor Advisory
- http://www.securityfocus.com/archive/1/468548/100/0/threaded mailing-listx_refsource_BUGTRAQThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/archive/1/468670/100/0/threaded mailing-listx_refsource_BUGTRAQThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/23974 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id?1018049 vdb-entryx_refsource_SECTRACKThird Party AdvisoryVDB Entry
- http://www.trustix.org/errata/2007/0017/ vendor-advisoryx_refsource_TRUSTIXBroken Link
- http://www.ubuntu.com/usn/usn-460-1 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- http://www.ubuntu.com/usn/usn-460-2 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- http://www.vupen.com/english/advisories/2007/1805 vdb-entryx_refsource_VUPENPermissions Required
- http://www.vupen.com/english/advisories/2007/2210 vdb-entryx_refsource_VUPENPermissions Required
- http://www.vupen.com/english/advisories/2007/2281 vdb-entryx_refsource_VUPENPermissions Required
- https://access.redhat.com/security/cve/CVE-2007-2444 Vendor Advisory
- https://issues.rpath.com/browse/RPL-1366 x_refsource_CONFIRMBroken Link
- https://nvd.nist.gov/vuln/detail/CVE-2007-2444
- https://www.cve.org/CVERecord?id=CVE-2007-2444
| Link | Providers | Tags |
|---|---|---|
| http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c01078980 | vendor-advisoryx_refsource_HPBroken Link | |
| http://lists.suse.com/archive/suse-security-announce/2007-May/0006.html | vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory | |
| http://osvdb.org/34698 | vdb-entryx_refsource_OSVDBBroken Link | |
| http://secunia.com/advisories/25232 | third-party-advisoryx_refsource_SECUNIAThird Party Advisory | |
| http://secunia.com/advisories/25241 | third-party-advisoryx_refsource_SECUNIAThird Party Advisory | |
| http://secunia.com/advisories/25246 | third-party-advisoryx_refsource_SECUNIAThird Party Advisory | |
| http://secunia.com/advisories/25251 | third-party-advisoryx_refsource_SECUNIAThird Party Advisory | |
| http://secunia.com/advisories/25255 | third-party-advisoryx_refsource_SECUNIAThird Party Advisory | |
| http://secunia.com/advisories/25256 | third-party-advisoryx_refsource_SECUNIAThird Party Advisory | |
| http://secunia.com/advisories/25259 | third-party-advisoryx_refsource_SECUNIAThird Party Advisory | |
| http://secunia.com/advisories/25270 | third-party-advisoryx_refsource_SECUNIAThird Party Advisory | |
| http://secunia.com/advisories/25289 | third-party-advisoryx_refsource_SECUNIAThird Party Advisory | |
| http://secunia.com/advisories/25675 | third-party-advisoryx_refsource_SECUNIAThird Party Advisory | |
| http://secunia.com/advisories/25772 | third-party-advisoryx_refsource_SECUNIAThird Party Advisory | |
| http://security.gentoo.org/glsa/glsa-200705-15.xml | vendor-advisoryx_refsource_GENTOOThird Party Advisory | |
| http://securityreason.com/securityalert/2701 | third-party-advisoryx_refsource_SREASONThird Party Advisory | |
| http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.475906 | vendor-advisoryx_refsource_SLACKWAREMailing ListThird Party Advisory | |
| http://sunsolve.sun.com/search/document.do?assetkey=1-26-102964-1 | vendor-advisoryx_refsource_SUNALERTBroken Link | |
| http://sunsolve.sun.com/search/document.do?assetkey=1-66-200588-1 | vendor-advisoryx_refsource_SUNALERTBroken Link | |
| http://www.debian.org/security/2007/dsa-1291 | vendor-advisoryx_refsource_DEBIANThird Party Advisory | |
| http://www.mandriva.com/security/advisories?name=MDKSA-2007:104 | vendor-advisoryx_refsource_MANDRIVABroken Link | |
| http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.012.html | vendor-advisoryx_refsource_OPENPKGThird Party Advisory | |
| http://www.samba.org/samba/security/CVE-2007-2444.html | x_refsource_CONFIRMPatchVendor Advisory | |
| http://www.securityfocus.com/archive/1/468548/100/0/threaded | mailing-listx_refsource_BUGTRAQThird Party AdvisoryVDB Entry | |
| http://www.securityfocus.com/archive/1/468670/100/0/threaded | mailing-listx_refsource_BUGTRAQThird Party AdvisoryVDB Entry | |
| http://www.securityfocus.com/bid/23974 | vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry | |
| http://www.securitytracker.com/id?1018049 | vdb-entryx_refsource_SECTRACKThird Party AdvisoryVDB Entry | |
| http://www.trustix.org/errata/2007/0017/ | vendor-advisoryx_refsource_TRUSTIXBroken Link | |
| http://www.ubuntu.com/usn/usn-460-1 | vendor-advisoryx_refsource_UBUNTUThird Party Advisory | |
| http://www.ubuntu.com/usn/usn-460-2 | vendor-advisoryx_refsource_UBUNTUThird Party Advisory | |
| http://www.vupen.com/english/advisories/2007/1805 | vdb-entryx_refsource_VUPENPermissions Required | |
| http://www.vupen.com/english/advisories/2007/2210 | vdb-entryx_refsource_VUPENPermissions Required | |
| http://www.vupen.com/english/advisories/2007/2281 | vdb-entryx_refsource_VUPENPermissions Required | |
| https://access.redhat.com/security/cve/CVE-2007-2444 | Vendor Advisory | |
| https://issues.rpath.com/browse/RPL-1366 | x_refsource_CONFIRMBroken Link | |
| https://nvd.nist.gov/vuln/detail/CVE-2007-2444 | ||
| https://www.cve.org/CVERecord?id=CVE-2007-2444 |
Change history (0)
No recorded changes yet.